CVE-2026-48070 | Docmost up to 0.80.0 Avatar Cleanup avatarUrl path traversal
A vulnerability was found in Docmost up to 0.80.0. It has been declared as problematic. Impacted is an unknown function of the component Avatar Cleanup. Executing a manipulation of the argument avatarUrl can lead to path traversal.
The identification of this vulnerability is CVE-2026-48070. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More